{"id":"CVE-2026-55401","title":"CVE-2026-55401 is a null dereference vulnerability on the load-balancing\n sub-system of Secure Access servers prior to 14.57","summary":"CVE-2026-55401 is a null dereference vulnerability on the load-balancing\n sub-system of Secure Access servers prior to 14.57. Attackers can send \nan unauthenticated packet to a Secure Access server with load balancing \nenabled, which res…","severity":"medium","cvss":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","cwe":["CWE-476"],"vendor":"absolute","product":"secure_access","affected":["secure_access < 14.57"],"patched":["secure_access 14.57"],"published":"2026-08-13","updated":"2026-09-04","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-55401","references":[{"url":"https://www.absolute.com/platform/security-information/vulnerability-archive/cve-2026-55401","label":"SecurityResponse@netmotionsoftware.com"}],"tags":["nvd"],"epss":0.00293,"epssPercentile":0.2213,"ingestedAt":"2026-09-05T17:42:35.568Z","slug":"CVE-2026-55401","body":"## Overview\n\nCVE-2026-55401 is a null dereference vulnerability on the load-balancing\n sub-system of Secure Access servers prior to 14.57. Attackers can send \nan unauthenticated packet to a Secure Access server with load balancing \nenabled, which results in the internal load balancer crashing. After a \nsuccessful attack, the Secure Access server is still able to accept \nconnections and is still able to issue a failover to connected clients. ‍ https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L\n\n## Affected\n\n- `secure_access < 14.57`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `secure_access 14.57`","depth":"sunlit","depthScore":29,"depthScoreParts":{"impact":29.2,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}